Azure容器应用环境中Nginx内部调用返回部分响应问题排查
问题:Azure容器应用中Nginx内部路由偶尔截断大响应
环境与部署情况
- 同一Azure容器应用环境下部署两个Docker容器:
- Nginx容器(repro-nginx)
- .NET WebAPI容器(repro-large-response),可生成73.7 kB的大响应
- Nginx配置3条路由:
/repro-internal/:通过内部服务名访问repro-large-response/repro-external-http/:通过Ingress以HTTP方式访问repro-large-response/repro-external-https/:通过Ingress以HTTPS方式访问repro-large-response
问题现象
访问/repro-internal/时,偶尔会返回部分响应(大小为65.5 kB,而非预期的73.7 kB),JSON数据被截断,部分浏览器会报NS_ERROR_NET_PARTIAL_TRANSFER错误;外部调用的两个端点无此问题。
相关镜像
镜像托管于Docker Hub:
- repro-nginx
- repro-large-response
Nginx配置文件
cors-options.conf
proxy_hide_header Access-Control-Allow-Origin; add_header 'Access-Control-Allow-Origin' $allow_origin; add_header Vary Origin; add_header 'Access-Control-Allow-Credentials' 'true'; add_header 'Access-Control-Allow-Methods' 'GET, POST, PUT, DELETE, OPTIONS'; add_header 'Access-Control-Allow-Headers' 'Accept,Authorization,Cache-Control,Content-Type,DNT,If-Modified-Since,Keep-Alive,Origin,User-Agent,X-Requested-With';
cors-map.conf
map $http_origin $allow_origin { default ""; }
/etc/nginx/conf.d/default.conf
include snippets/cors-map.conf; server { listen 80; # server_name frontend; # error_log /home/logs/error.log debug; location / { root /usr/share/nginx/html; try_files $uri /index.html; } location /health { access_log off; error_log off; add_header 'Content-Type' 'application/json'; return 200 '{"status":"UP"}'; } proxy_read_timeout 300; proxy_connect_timeout 300; proxy_send_timeout 300; client_max_body_size 500M; client_body_buffer_size 500M; client_body_timeout 300; client_header_timeout 300; keepalive_timeout 300; proxy_buffer_size 128k; proxy_buffers 4 256k; proxy_busy_buffers_size 256k; location /repro-internal/ { include snippets/cors-options.conf; proxy_ssl_server_name on; proxy_set_header X-Real-IP $remote_addr; proxy_set_header Authorization "Bearer null"; proxy_pass http://repro-large-response/; proxy_http_version 1.1; } location /repro-external-http/ { include snippets/cors-options.conf; proxy_ssl_server_name on; proxy_set_header X-Real-IP $remote_addr; proxy_set_header Authorization "Bearer null"; proxy_pass http://repro-large-response.lemonsea-adf71d13.westeurope.azurecontainerapps.io/; proxy_redirect off; proxy_http_version 1.1; } location /repro-external-https/ { include snippets/cors-options.conf; proxy_ssl_server_name on; proxy_set_header X-Real-IP $remote_addr; proxy_set_header Authorization "Bearer null"; proxy_pass https://repro-large-response.lemonsea-adf71d13.westeurope.azurecontainerapps.io/; proxy_redirect off; proxy_http_version 1.1; } }
Terraform部署配置片段
// Container app - repro-large-response resource "azurerm_container_app" "repro-large-response" { name = "repro-large-response" container_app_environment_id = azurerm_container_app_environment.main.id resource_group_name = azurerm_resource_group.main.name revision_mode = "Single" identity { type = "SystemAssigned" } ## Issue when deploying inmediately with ingress enabled ingress { external_enabled = true target_port = 8080 allow_insecure_connections = true traffic_weight { percentage = 100 latest_revision = true } } template { min_replicas = 1 max_replicas = 1 container { name = "repro-large-response" image = "techorama2021cegeka/repro-large-response:3" cpu = 0.25 memory = "0.5Gi" } } tags = { "container" = "repro-large-response" } } // Container app - repro-nginx resource "azurerm_container_app" "repro-nginx" { name = "repro-nginx" container_app_environment_id = azurerm_container_app_environment.main.id resource_group_name = azurerm_resource_group.main.name revision_mode = "Single" identity { type = "SystemAssigned" } ## Issue when deploying inmediately with ingress enabled ingress { external_enabled = true target_port = 80 allow_insecure_connections = false traffic_weight { percentage = 100 latest_revision = true } } template { min_replicas = 1 max_replicas = 1 container { name = "repro-nginx" image = "techorama2021cegeka/repro-nginx:4" cpu = 0.25 memory = "0.5Gi" } } tags = { "container" = "repro-nginx" } }
内容的提问来源于stack exchange,提问作者user24438114
相关产品推荐
相关产品推荐

